GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and FlockWiper-Derived Multi-Pass Wiping
GigaWiper (BLUERABBIT) (TL-2026-1271), also tracked as GigaWiper, is a high-severity malware campaign, first published 2026-07-13. It is attributed to BLUERABBIT (Iran) with medium confidence, affects Microsoft Windows (all versions supporting WMI, Task Scheduler, maps to 28 MITRE ATT&CK techniques (T1012, T1016, T1021.005), and is covered by 9 detection rules and 32 indicators of compromise.
Key facts for TL-2026-1271
- Threat ID
- TL-2026-1271
- Also known as
- GigaWiper, BLUERABBIT
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-13
- Last reviewed
- 2026-07-13
- Attribution
- BLUERABBIT
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- government administration, criticalinfrastructure, energy, waterutilities, unspecifiedgeneral
- Target regions
- israel, Middle East
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in GigaWiper (BLUERABBIT)
Malware and tooling: BLUERABBIT, BLUEWIPE, Crucio, FlockWiper, GigaWiper, SEWERGOO, RabbitMQ, Redis
Microsoft Threat Intelligence identified GigaWiper, a Go-based backdoor active since October 2025 that fuses a standalone physical-disk wiper, a Crucio-ransomware-derived unrecoverable file-encryption command, and a reimplemented FlockWiper multi-pass drive-wiping routine into a single C2-controlled implant on Windows systems. Google Threat Intelligence Group and Binary Defense track the same malware as BLUERABBIT and assess it as part of an Iran-nexus cluster linked to prior IRGC-affiliated CyberAv3ngers activity (Crucio, December 2023 CISA advisory) that also produced BLUEWIPE and SEWERGOO. The implant gives operators on-demand choice between quiet espionage (screen capture/recording, keylogging, VNC-like remote access, system profiling) and destructive sabotage (raw sector wiping, BSOD triggering, .candy-extension fake ransomware, event-log deletion).
How GigaWiper (BLUERABBIT) works
GigaWiper is a modular, Golang-compiled backdoor first observed conducting destructive wiping activity in October 2025 and publicly disclosed by Microsoft on 2026-07-09. It is architecturally distinctive for consolidating THREE previously distinct malware lineages into a single 20-command implant rather than deploying them as separate tools: (1) a standalone physical-disk wiper that is code-identical to the backdoor's own Command 1/WipeMain, suggesting the wiper was cannibalized into the backdoor or vice versa; (2) a file-encryption/destruction command (Command 3, internally named RanMain/BigBangExtortMain) whose code traces to Crucio ransomware, a malware family a December 2023 CISA advisory attributed to IRGC-affiliated cyber actors following attacks on US, UK, Irish, and Israeli water and energy infrastructure; and (3) a multi-pass secure-wipe command (Command 12, WipeCMain) that is a Golang reimplementation of FlockWiper, a C-language wiper that first surfaced on VirusTotal in June 2025, months before GigaWiper's own operational debut.
Attribution linkage across the three lineages rests on shared function naming (BigBangExtortMain appears in both Crucio and GigaWiper), identical code flow, string overlap, and a recurring "GRAT" tag that appears both in FlockWiper's PDB debug paths (A:\GRAT\CWipeNew\Release\CWipeNew.pdb and E:\files\new\GRAT\CWipe\Release\CWipe.pdb) and throughout GigaWiper's internal function names — indicating the existence of an undiscovered "GRAT" development framework shared across the toolset. Google Threat Intelligence Group and Binary Defense track the family as BLUERABBIT and assess it, per Binary Defense reporting, as an Iran-nexus cluster targeting Israeli organizations, part of the same operational grouping that deployed BLUEWIPE and SEWERGOO in June 2025. Microsoft's own reporting declines to attribute a specific nation-state. Binary Defense first observed BLUERABBIT samples in March 2026; Microsoft dates the destructive activity itself to October 2025.
Operationally, GigaWiper communicates over RabbitMQ (AMQP) for command tasking — using a fanout exchange named "All" for broadcast commands and a topic exchange named "Topic" for targeted commands managed via Command 8's bind/unbind routing — and over Redis on non-standard ports for status/result reporting (fields: error, target_ip, task_id, target_computer_name, output, pwd, time, status, work_status). Both channels use an encrypted, hard-coded AES configuration. Data can be exfiltrated via a bundled MinIO client (Command 4). Persistence is established via a scheduled task named "OneDrive Update" that runs every minute plus at startup, with execution counts tracked in HKCU\SOFTWARE\OneDrive\Environment; the implant masquerades a firewall rule as "Microsoft.Windows.CloudExperienceHost" to cloak its VNC-like remote-desktop command (Command 20).
The destructive tier gives the operator three distinct escalation levers on a single infected host: Command 1 (WipeMain) enumerates physical drives via WMI, removes non-Windows-drive partition metadata via IOCTL_DISK_CREATE_DISK, and overwrites raw sectors in 0xA00000-byte chunks with a randomized (or fallback constant "1") first byte and zero-padded remainder, then forces an immediate zero-delay reboot; Command 2 triggers a BSOD via registry/boot-file deletion; Command 3 (RanMain/BigBangExtortMain) performs AES-CBC encryption in chunks with a randomly generated key/IV that is never persisted anywhere (making the encryption cryptographically unrecoverable — a "fake ransomware" that drops no ransom note and excludes .exe/.dll from encryption, deleting originals after encrypting), applying the .candy extension and dropping ./image_danger.jpg as a wallpaper; Command 12 (WipeCMain) performs FlockWiper-style multi-pass secure wiping restricted to the Windows drive — pass 1 zeros, pass 2 0xFF bytes, pass 3 random bytes, with inter-pass timing reported back to the operator.
Espionage/management tradecraft includes Command 5 (AES-256-CBC file encrypt/decrypt utility, key stored in key.txt), Command 7 (PowerShell execution appending a directory-tracking marker ";"|?????|$pwd""), Command 9 (per-monitor PNG screenshot capture), Command 10 (screen recording to C:\ProgramData\output when the user is active and the system unlocked), Command 11 (an unpopulated keylogger stub), Command 15 (system/network/firmware/AV profiling), Command 16 (process manager), Command 17 (service manager), Command 18 (interactive registry manager), Command 19 (deletion of System, Setup, Application, ForwardedEvents, and Security Windows event logs), and Command 20 (VNC-like remote desktop). Commands 6, 13, and 14 are unpopulated/unimplemented placeholders reserved for future wiper or escalation logic, underscoring the implant's modular, still-evolving design.
MITRE ATT&CK techniques used in TL-2026-1271
Discovery
T1012 Query Registry; T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
Lateral Movement
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1497 Virtualization/Sandbox Evasion
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Persistence
T1053.005 Scheduled Task; T1547.005 Security Support Provider
Collection
T1056.001 Keylogging; T1113 Screen Capture; T1125 Video Capture
Command and Control
T1071.002 File Transfer Protocols; T1219 Remote Access Tools; T1571 Non-Standard Port
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1529 System Shutdown/Reboot; T1561.002 Disk Structure Wipe
defense-impairment
T1685 Disable or Modify Tools; T1685.002 Disable or Modify Cloud Log; T1685.005 Clear Windows Event Logs; T1686 Disable or Modify System Firewall
Affected products and versions in GigaWiper (BLUERABBIT)
- Microsoft — Windows (all versions supporting WMI, Task Scheduler, Windows Event Log, and NTFS/disk IOCTL operations)
Vulnerable versions: Windows client and server OS generally
Remediation for GigaWiper (BLUERABBIT)
Immediate actions
- Block C2 IP infrastructure 185.182.193.21 (RabbitMQ port 5544, Redis port 7542) and 212.8.248.104 at network perimeter/firewall
- Hunt for scheduled task named 'OneDrive Update' configured to run every minute plus at startup
- Hunt for registry key HKCU\SOFTWARE\OneDrive\Environment
- Hunt for firewall rules referencing 'Microsoft.Windows.CloudExperienceHost' that do not correspond to legitimate Windows components
- Isolate hosts showing raw disk IOCTL_DISK_CREATE_DISK activity or mass Windows Security/System/Application/Setup/ForwardedEvents event-log clearing
- Search for files with .candy extension and ./image_danger.jpg wallpaper artifact indicating active Command 3 destructive encryption
- Preserve immutable/offline backups given the encryption used by Command 3 is cryptographically unrecoverable (key/IV never persisted)
Workarounds
- Restrict outbound AMQP (5672 and non-standard variants) and Redis (6379 and non-standard variants) traffic to only known-good destinations
- Enforce offline/air-gapped backup cadence for systems where disk-wipe or ransomware-style destruction would be catastrophic
Longer-term hardening
- Deploy EDR with behavioral detection tuned to raw disk sector overwrite patterns and IOCTL_DISK_CREATE_DISK calls
- Enable Microsoft Defender Attack Surface Reduction rule to block executable files that do not meet prevalence/age/trusted-list criteria
- Enable tenant-wide Tamper Protection and disable GPO admin merge to prevent AV exclusion tampering
- Segment critical infrastructure (water/energy sector systems historically targeted by this cluster via Crucio) from general IT networks
- Deploy network detection for RabbitMQ/AMQP and Redis protocol traffic to unexpected external hosts on non-standard ports
Timeline of GigaWiper (BLUERABBIT)
- CISA publishes advisory attributing Crucio ransomware to IRGC-affiliated cyber actors following attacks on US, UK, Irish, and Israeli water and energy infrastructure — code later reused inside GigaWiper's Command 3.
- Same Iran-nexus cluster reported to have deployed BLUEWIPE and SEWERGOO malware, per Binary Defense/Google Threat Intelligence Group.
- FlockWiper, a C-language wiper later reimplemented in Golang as GigaWiper Command 12, first appears on VirusTotal.
- Microsoft Threat Intelligence dates the start of observed GigaWiper destructive wiping activity in the wild.
- Binary Defense first observes BLUERABBIT (GigaWiper) samples independently.
- Dark Reading publishes coverage syndicating the Microsoft disclosure.
- Microsoft Security Blog publishes 'GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware,' the primary technical disclosure.
- The Hacker News, SecurityWeek, CSO Online, TechTimes, Cyberpress, OSINTsights, Hackread, and The Register publish follow-on coverage, several citing Google Threat Intelligence Group and Binary Defense attribution to an Iran-nexus cluster targeting Israeli organizations.
Sources cited for GigaWiper (BLUERABBIT)
- GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
- GigaWiper: Threat actors choose their own destructive attack
- New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
- GigaWiper: Modular Windows Backdoor Combines Disk Wiper, Fake Ransomware, Spyware
- Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand
- GigaWiper Combines Multiple Malware for System-Level Sabotage
- Microsoft Warns GigaWiper Merges Crucio and FlockWiper Code Into Destructive Backdoor
- Microsoft Exposes GigaWiper Backdoor's Triple Threat
- Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs
- Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
- CISA Advisory: IRGC-Affiliated Cyber Actors (Crucio ransomware, water/energy infrastructure attacks)
Threats related to GigaWiper (BLUERABBIT)
- GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities
- GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware, and FlockWiper Drive Overwriter Behind Espionage Tooling
Detection coverage for TL-2026-1271
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1271 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.